Q: Shib IdP behaviour for key roll over and ADFS
Tom Scavo
trscavo at gmail.com
Tue Feb 18 17:01:58 EST 2014
On Tue, Feb 18, 2014 at 11:42 AM, Chris Phillips
<Chris.Phillips at canarie.ca> wrote:
>
> Digging deeper, much of the challenge has been (for me) around IdPs
> automatically encrypting assertions when the key I have in metadata is
> really a signing key which was the wrong key to use without properly
> decorating it with 'use=signing'.
Chris, I'm getting mixed messages from the discussion so far. Earlier
you said you have a KeyDescriptor in SP metadata with no 'use'
attribute. That means that IdPs *will* use it for encryption, so I'm
not sure what the problem is.
> I will likely pursue the approach of tagging the key 'use=signing' like
> others I've seen in inCommon metadata once I've exercised it internally.
Are you talking about SP metadata? Yes, InCommon SPs can (and do)
manipulate the 'use' attribute for key rollover purposes but in
exactly the opposite manner I heard you describe. The sequence of
steps is documented in the space wiki:
https://spaces.internet2.edu/x/dpiKAQ
Also, Scott asked the critical question: Can the AD FS SP be
configured with two decryption keys? If not, you're screwed.
Tom
More information about the users
mailing list